industry

SPRS Score Calculator for Small Business DoD Contractors

Self-score CMMC / NIST SP 800-171 without a consultant for every step — built for small DoD contractors.

Small defense contractors carry the same NIST SP 800-171 obligations as the primes — the requirements don't scale down with headcount. If you handle CUI, you need a current, defensible SPRS score to stay eligible for award, whether you're 5 people or 500.

What's different is leverage: leaner teams, tighter budgets, no dedicated compliance staff. The good news is that scope, not size, drives the work — a small shop that handles CUI on a handful of systems has a much smaller assessment than its system count suggests, once assets are categorized under 32 CFR 170.19.

The pragmatic path: determine your level, scope tightly to the systems that actually hold CUI, self-assess at the objective level to find your real gaps, then bring in outside help only where remediation genuinely needs it — rather than paying a consultant for every step.

What's typically in scope for Small Business Contractors

How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.

AssetCategoryWhat it means
The handful of systems (laptops, file storage, email) where CUI lives
CUI
In scope as CUI Assets — keep this set as small as you can.
A managed IT/security provider you rely on
Security Protection
An ESP / Security Protection Asset — assessed against its capability; document it in the SSP + CRM.
Productivity cloud (email/file) that stores CUI
CUI
If it holds CUI it's in scope; a CUI-handling cloud must meet FedRAMP Moderate or equivalency.
Personal/BYOD or general office systems kept clear of CUI
Out-of-Scope
Out of scope if genuinely separated and CUI never lands there — be ready to justify it.

Where Small Business Contractors teams usually focus

Common areas to shore up — your real gaps come from the assessment, not a generic list.

  • Tight scoping so a small system count stays a small assessment
  • MFA and access control (often the highest-impact early wins)
  • FIPS-validated encryption on the systems that hold CUI
  • A real System Security Plan — its absence blocks a complete assessment
  • A POA&M with owners and dates for the gaps you can't close yet
Map the 800-171 ↔ CMMC controls

Which CMMC level you need

FCI-only work is Level 1 (15 FAR 52.204-21 safeguards). Any CUI raises the floor to Level 2 (the 110 requirements). The level-determination wizard helps you confirm which applies before you start.

Run the level-determination wizard

What you need to know

  • Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
  • A score of 110 is a Final self-assessment; 88109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
  • A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Read the full walkthrough

Clauses that likely apply to you

DFARS 252.204-7012
DFARS 252.204-7019
DFARS 252.204-7021
See what each clause requires
SentryNexus scoring dashboard: 106 of 110 but No CMMC Status — one disqualifying gap that can't be placed on a POA&M.
A 106/110 that's still “No CMMC Status” — one disqualifying gap that can't be deferred (32 CFR 170.21). The split a score-only calculator misses.

Know your score before you submit

Run a full 110-requirement self-assessment free — no account required to see your score.

Start free assessment

Free tools

Frequently asked questions

Do small businesses really have to do this?
Yes. NIST SP 800-171 obligations do not scale down with company size. If you handle CUI, you need a current SPRS score regardless of headcount.
Do I need a consultant?
Not necessarily for the self-assessment. A guided, objective-level tool lets many small contractors self-assess; you can bring in help for remediation where it is needed.
How much does compliance cost?
It varies with your gaps. The assessment itself is free here — the real cost is remediating not-met requirements, so start by scoring to see where you stand.
Where should a small contractor start?
Run the level-determination wizard, then scope to the systems that actually handle CUI — that single step often shrinks the work more than anything else. Then self-assess at the objective level to see your true gaps.
Is a System Security Plan really required for a small business?
Yes. The SSP (3.12.4) is a prerequisite, not a scored line item — without it an assessment can't be completed (and it signals noncompliance with DFARS 252.204-7012). Even a lean, accurate SSP satisfies it.

Related industries

Related guides

Go deeper on scoring, levels, and POA&Ms.